29 Aug
|
River
|
Bengaluru
About River River is a design company building multi-utility products.
Our flagship product River Indie, #SUVofScooters, is designed to help you get things done. Engineered to be a dependable ally on your road to success.
We’re a 1000+ team headquartered in Bengaluru – backed by marquee international investors, with mobility-focused funds linked to Yamaha Motors, Al-Futtaim Automotive Group, Toyota VC, Trucks Venture Capital, Mitsui & Co. Ltd, Marubeni Ventures Inc., Lowercarbon Capital, and Maniv Mobility.
Key Responsibilities
- Think end to end across domains: assess risk, connect signals, and advance our zero trust architecture in partnership with the network (Cisco Meraki) and cloud teams — strengthening the whole environment, not one tool
- Harden and monitor AWS (IAM, VPC, security groups, S3, CloudTrail/GuardDuty); remediate misconfigurations against CIS Benchmarks and embed guardrails so issues stay fixed
- Act as our internal counterpart to CrowdStrike Falcon Complete: handle escalations, validate containment and remediation, and own prevention policy, sensor, and exclusion hygiene across Windows and Linux fleets
- Onboard and parse log sources, build correlation rules and dashboards in NG-SIEM, automate response workflows with Fusion SOAR, and manage our tiered log architecture (high-value sources into SIEM, bulk logs to S3 archive)
- Defend the identity plane (Google Workspace SSO): detect credential misuse, token theft, and OAuth abuse; reduce standing privileges; govern non-human identities (service accounts, API keys, AI agents); tune email security and lead phishing response
- Go beyond periodic scanning:
use CrowdStrike Falcon Exposure Management to prioritise by real-world exploitability and attack paths, drive remediation through Freshservice, and report on exposure reduction, not just patch counts
- Lead response for incidents beyond MDR scope — cloud, identity, email, network — per the NIST IR lifecycle, and run proactive hunts across telemetry in NG-SIEM mapped to MITRE ATTACK, with transparent, audit-ready documentation
- Defend against AI-enabled attacks (LLM-crafted phishing, deepfake- assisted social engineering) and supply chain risks (software provenance, golden image and installation media integrity); help govern the company's own safe adoption of AI tools
- Produce evidence for ISO 27001:2022, ISO 27701, and SOC 2 audits, and operate day-to-day controls with DPDP Act 2023 obligations built in — treating compliance as an output of good engineering, not a separate chore
Ideal Candidate
- B.E. / B.Tech / M.Tech in Information Technology, Computer Science, or Cybersecurity — or equivalent practical experience
- Minimum 3 years of hands-on cybersecurity experience spanning threat detection, incident response, and cloud security
- Hands-on experience with at least three domains (cloud, endpoint, SIEM, identity, network, IR); AWS security experience; CrowdStrike Falcon platform experience; SIEM detection engineering (NG-SIEM/LogScale preferred); CCNA-level networking; Python/Bash and API-driven automation
- Good to have AWS Security Specialty, CCFA/CCFR, Security+/CEH; MDR collaboration experience; ISO 27001/SOC 2 exposure; automotive cybersecurity interest (ISO/SAE21434)
📌 Cybersecurity Engineer (Bengaluru)
🏢 River
📍 Bengaluru